Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Glab Cli

ASecurity

Use glab for GitLab MRs, issues, discussions, pipelines, notes, labels, and raw API tasks.

4 stars
0 votes
0 copies
0 views
Added 9/25/2026
documentationbashgitapi

Works with

cliapi

Security Analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned 9/25/2026

$npx -y skills add colinmollenhour/dotfiles --skill glab-cli --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Glab Cli?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Glab Cli
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/colinmollenhour-glab-cli/badge)](https://www.skillsdirectory.com/skills/colinmollenhour-glab-cli)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: glab-cli
user-invocable: false
description: 'Use glab for GitLab MRs, issues, discussions, pipelines, notes, labels, and raw API tasks.'
---

# GitLab CLI

Prefer `glab` over browser workflows. **Prefer bundled scripts over multi-step chat archaeology.**

## Scripts first

| Need | Script |
|---|---|
| Full MR context (view+notes+discussions+versions+diff) | `bun "${CLAUDE_SKILL_DIR}/mr-context.ts" --project G/R --mr N --out-dir .tmp/mr-N` |
| Create/update MR + optional note (commit-and-push path) | `bun "${CLAUDE_SKILL_DIR}/ship-mr.ts" --project G/R --title "…" --description-file body.md [--note-file note.md]` |
| Failed CI for branch/MR | `bun "${CLAUDE_SKILL_DIR}/ci-fail.ts" --project G/R --branch B --out-dir .tmp/ci` |

Each prints a **JSON summary** on stdout; large payloads stay on disk. Do not re-fetch the five MR endpoints one-by-one when `mr-context` covers it. Do not load this whole skill for a routine ship — run `ship-mr.ts`.

Detailed flag encyclopedia and edge cases: [reference.md](reference.md).

## Workflow

1. Resolve project (`git remote` / URL) and target (MR iid, branch, pipeline).
2. Prefer a script above, else high-level `glab` with `--output json` + `jq`.
3. Use `glab api` for gaps. `:fullpath` / `:id` resolve from **cwd git remote** — run inside the repo or pass numeric project id / `-R`.
4. Non-interactive flags only (`--yes`, `--title`, …).
5. Keep tool output tight — summarize; point at files under `.tmp/`.

## Cheat sheet

```bash
glab mr view <iid> -R <project> --output json
glab mr list --source-branch "$(git branch --show-current)" -R <project> --output json
glab mr note <iid> -R <project> -m "text"
glab ci list --per-page 3 --output json
glab api "projects/:fullpath/merge_requests/<iid>/discussions?per_page=100"  # paginate!
```

## Pitfalls (encoded in scripts when possible)

- **Pagination is mandatory** for notes/discussions — missing a page falsely reports "all resolved". `mr-context.ts` paginates.
- **`-f` is not file upload.** `-f description=@body.md` sends the literal string `@body.md`. Use `--input` + `Content-Type: application/json` for raw JSON bodies, `--form "file=@path"` for multipart uploads.
- Long MR descriptions: create MR, then PUT description via API JSON (`ship-mr.ts` does this).
- Upload embeds: use response `markdown` / `url` fields — **never** `full_path` (breaks rendering). Verify with `glab api /markdown` from inside the repo.
- Do not validate upload URLs with `PRIVATE-TOKEN` curl (session-only routes).

## Inline discussions

Fetch version SHAs first; post via discussions API with `position` (+ `line_range` if multi-line). Verify `"type": "DiffNote"`. One comment per issue. Suggestion blocks: multi-line needs `` ```suggestion:-N+M `` — see [reference.md](reference.md#committable-suggestion-blocks).

## Failure handling

Surface auth/access errors; say when no MR/pipeline matches; re-fetch after mutations when confirmation matters.

Attribution

colinmollenhourcolinmollenhour
View sourceSee grades on GitHubMore from colinmollenhour →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Context Fundamentals

Understand the components, mechanics, and constraints of context in agent systems. Use when designing agent architectures, debugging context-related failures, or optimizing context usage.

179001 votes

Architecture Diagram Creator

Create comprehensive HTML architecture diagrams with data flows, business context, and system architecture.

6661 votes

release-notes

Draft release notes and changelog entries from git history or merged PRs between two refs (tags/SHAs/branches), including breaking changes, migrations, and upgrade steps. Use when the user asks for release notes, changelog updates, or a GitHub Release draft.

1301 votes

docs-style-guide

Documentation style guide enforcer by @planetabhi. Applies and reviews the writing style guide when authoring or editing product documentation and tutorials. Use to check prose for voice, tense, word choice, inclusive language, formatting, code block, UI, Markdown, and number/date conventions.

11 votes

Docx

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in W...

1798860 votes
View all in documentation →